CVE-2026-19812
8.8TOTOLINK · A800R
A stack-based buffer overflow in the UploadCustomModule function of the TOTOLINK A800R router allows remote code execution via manipulation of the File argument.
Executive summary
A critical memory corruption flaw in TOTOLINK A800R routers enables remote code execution, requiring immediate attention to mitigate unauthorized access.
Vulnerability
This vulnerability is a stack-based buffer overflow within the UploadCustomModule function of the product.so component. It can be triggered remotely by an authenticated user manipulating the File argument.
Business impact
With a CVSS score of 8.8, this flaw presents a substantial risk to organizational security. An attacker capable of exploiting this memory corruption can gain control over the router, potentially leading to persistent device compromise, data interception, or the establishment of a foothold within the internal network.
Remediation
Immediate Action: Seek guidance from the vendor for potential firmware fixes. In the absence of a direct patch, disable unnecessary features or access to the affected module.
Proactive Monitoring: Review system logs for unusual file upload activity or unexpected process terminations related to the product.so component.
Compensating Controls: Utilize a Web Application Firewall or similar inspection tool to block malicious payloads directed at the /cgi-bin/cstecgi.cgi path.
Exploitation status
Public Exploit Available: Yes, a public exploit is available via the referenced GitHub repository.
Analyst recommendation
The severity of this remote code execution vulnerability demands prompt action. Organizations should prioritize the implementation of network-level defenses to prevent unauthorized access to the management interface while awaiting an official firmware update from the vendor.